CVE-2025-32711
M365 Copilot Information Disclosure Vulnerability
Description
Ai command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.
INFO
Published Date :
June 11, 2025, 2:15 p.m.
Last Modified :
Feb. 20, 2026, 5:25 p.m.
Remotely Exploit :
Yes !
Source :
[email protected]
CVSS Scores
| Score | Version | Severity | Vector | Exploitability Score | Impact Score | Source |
|---|---|---|---|---|---|---|
| CVSS 3.1 | CRITICAL | [email protected] | ||||
| CVSS 3.1 | HIGH | [email protected] |
Solution
- Update M365 Copilot to the latest version.
- Apply vendor patches promptly.
- Review access controls and configurations.
Public PoC/Exploit Available at Github
CVE-2025-32711 has a 107 public
PoC/Exploit available at Github.
Go to the Public Exploits tab to see the list.
References to Advisories, Solutions, and Tools
Here, you will find a curated list of external links that provide in-depth
information, practical solutions, and valuable tools related to
CVE-2025-32711.
| URL | Resource |
|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-32711 | Vendor Advisory |
| https://www.aim.security/lp/aim-labs-echoleak-m365 |
CWE - Common Weakness Enumeration
While CVE identifies
specific instances of vulnerabilities, CWE categorizes the common flaws or
weaknesses that can lead to vulnerabilities. CVE-2025-32711 is
associated with the following CWEs:
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Attack Pattern Enumeration and Classification
(CAPEC)
stores attack patterns, which are descriptions of the common attributes and
approaches employed by adversaries to exploit the CVE-2025-32711
weaknesses.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
costrict-plugins mirror of github-trending-slack-channel (auto-generated, do not edit)
TypeScript Gherkin
None
HTML Python
A zero-click prompt-injection (EchoLeak-style) lab and the defense that stops it.
ai-security llm-security owasp prompt-injection python rag security
Python
AI 防污染 Proxy — 一行代码接入,自动隔离 session/tenant/rag/inference 4 层污染
Dockerfile TypeScript Shell
None
Python HTML JavaScript CSS
Two-layer screener for indirect prompt injection in untrusted files, PDFs and web pages — run it before an LLM agent reads them. A deterministic pass catches hidden text (white/zero-width/metadata/off-canvas); a quarantined LLM (OpenRouter) catches visible EchoLeak-style exfiltration prose. Optional Claude Code skill + hooks.
Python
Defensive detection for indirect prompt injection (IPI) in agentic LLM systems
Python
A practical threat model for AI agents that use tools, browsers, files, terminals, APIs, and cloud resources. Organized around trust boundaries and mapped to OWASP ASI and LLM Top 10.
agent-security ai-security cloud-security llm-security mcp owasp prompt-injection red-team security threat-modeling
Governing the AI agents that govern your compliance — OWASP Agentic Top 10 mapped to GRC platforms with ISO 42001 controls
Python
Autorea Security Lab — OWASP LLM01 (Prompt Injection): a vulnerable vs. fixed email agent built from scratch (Python, OpenAI API), demonstrating three defense layers with measured before/after results.
Python
None
AISec Plus Week 1 threat write-up — EchoLeak (CVE-2025-32711), zero-click indirect prompt injection in Microsoft 365 Copilot.
Two structural MCP-layer vulnerabilities in Claude Code allowing usage of CC without limitations (tool-result injection, tool-description poisoning).
Shell JavaScript C Makefile
None
JavaScript HTML CSS TypeScript
None
HTML
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2025-32711 vulnerability anywhere in the article.
-
The Hacker News
One-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal Emails, Files, and MFA Codes
A single click on a trusted Microsoft link could have let an attacker pull emails, calendar details, and indexed files out of Microsoft 365 Copilot Enterprise Search. Researchers at Varonis Threat Lab ... Read more
-
NVISO Labs
Securing AI systems without overconfidence or fear – Part 2: Attack surfaces and the checkpoint flow
Document information Series Securing AI systems without overconfidence or fear Part 2 of 5 Title Attack surfaces and the checkpoint flow Date May 2026 Author Hussein Bahmad (NVISO) Reading time ~13 mi ... Read more
-
TheCyberThrone
The Exploit That Arrived in an Email and Left With Your Data
The Distinction Nobody Makes Clearly EnoughWhen most practitioners hear “prompt injection,” they picture a user typing malicious instructions directly into a chatbot. “Ignore previous instructions. Re ... Read more
-
CybersecurityNews
New One-Click Microsoft Copilot Vulnerability Grants Attackers Undetected Access to Sensitive Data
A novel single-click attack targeting Microsoft Copilot Personal that enables attackers to silently exfiltrate sensitive user data. The vulnerability, now patched, allowed threat actors to hijack sess ... Read more
-
CybersecurityNews
One Year Of Zero-Click Exploits: What 2025 Taught Us About Modern Malware
The year 2025 represents a pivotal moment in cybersecurity, showcasing a remarkable evolution in zero-click exploitation techniques that significantly challenges our understanding of digital security. ... Read more
-
Help Net Security
Cato Networks acquires Aim Security to bring AI protection into SASE Cloud
Cato Networks acquired Aim Security to further enhance the Cato SASE Cloud Platform, supporting secure enterprise adoption of AI agents and both public and private AI applications. Cato has now exceed ... Read more
-
CybersecurityNews
Weekly Cybersecurity News Recap : Apple 0-day, Chrome, Copilot Vulnerabilities and Cyber Attacks
This past week was packed with high-severity disclosures and active exploitation reports across the global threat landscape. At the forefront, Apple rushed out emergency patches for yet another zero-d ... Read more
-
Hackread - Latest Cybersecurity, Hacking News, Tech, AI & Crypto
AgentFlayer 0-click exploit abuses ChatGPT Connectors to Steal 3rd-party app data
AgentFlayer is a critical vulnerability in ChatGPT Connectors. Learn how this zero-click attack uses indirect prompt injection to secretly steal sensitive data from your connected Google Drive, ShareP ... Read more
-
Trend Micro
Preventing Zero-Click AI Threats: Insights from EchoLeak
Key Takeaways EchoLeak is a zero-click AI vulnerability that exploits Copilot’s use of historical contextual data to silently execute hidden prompts without user interaction. The attack method relies ... Read more
-
TheCyberThrone
EchoLeak Vulnerability in Microsoft 365 Copilot
Skip to contentOverviewEchoLeak is a critical zero-click vulnerability found in Microsoft 365 Copilot, revealed in 2025 by AIM Security. The flaw allowed attackers to steal sensitive enterprise data w ... Read more
-
databreaches.net
Copilot AI Bug Could Leak Sensitive Data via Email Prompts
Rashmi Ramesh reports: A well-phrased email was all an attacker would have needed to trick Microsoft Copilot into handing over sensitive data until the operating system giant patched the vulnerability ... Read more
-
Google Online Security Blog
Mitigating prompt injection attacks with a layered defense strategy
With the rapid adoption of generative AI, a new wave of threats is emerging across the industry with the aim of manipulating the AI systems themselves. One such emerging attack vector is indirect prom ... Read more
-
SentinelOne
More From Our Main Blog: The Good, the Bad and the Ugly in Cybersecurity – Week 24
The Good | Operation Secure Dismantles Global Infostealer Infrastructure in Multi-Nation Crackdown An international law enforcement initiative dubbed “Operation Secure” delivered a significant blow to ... Read more
-
Dark Reading
Researchers Detail Zero-Click Copilot Exploit 'EchoLeak'
Source: Adrian Vidal via Alamy Stock PhotoA critical vulnerability could have enabled attackers to unleash prompt injection attacks against Copilot users, though Microsoft ultimately addressed the iss ... Read more
-
The Hacker News
Zero-Click AI Vulnerability Exposes Microsoft 365 Copilot Data Without User Interaction
A novel attack technique named EchoLeak has been characterized as a "zero-click" artificial intelligence (AI) vulnerability that allows bad actors to exfiltrate sensitive data from Microsoft 365 Copil ... Read more
-
BleepingComputer
Zero-click AI data leak flaw uncovered in Microsoft 365 Copilot
A new attack dubbed 'EchoLeak' is the first known zero-click AI vulnerability that enables attackers to exfiltrate sensitive data from Microsoft 365 Copilot from a user's context without interaction. ... Read more
The following table lists the changes that have been made to the
CVE-2025-32711 vulnerability over time.
Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.
-
CVE Modified by [email protected]
Feb. 20, 2026
Action Type Old Value New Value Added CWE CWE-74 Removed CWE CWE-77 -
CVE Modified by af854a3a-2127-422b-91ae-364da2661108
Aug. 04, 2025
Action Type Old Value New Value Added Reference https://www.aim.security/lp/aim-labs-echoleak-m365 -
Initial Analysis by [email protected]
Jul. 10, 2025
Action Type Old Value New Value Added CVSS V3.1 AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Added CPE Configuration OR *cpe:2.3:a:microsoft:365_copilot:-:*:*:*:*:*:*:* Added Reference Type Microsoft Corporation: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-32711 Types: Vendor Advisory -
New CVE Received by [email protected]
Jun. 11, 2025
Action Type Old Value New Value Added Tag exclusively-hosted-service Added Description Ai command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network. Added CVSS V3.1 AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N Added CWE CWE-77 Added Reference https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-32711